Eanet, PC in Los Angeles and Rolling Hills Estates - Serving Clients Statewide

California Privacy Agency Launches First Sectoral Audit, Targets Gig Economy Platforms

California Privacy Agency Launches First Sectoral Audit, Targets Gig Economy Platforms

The California Privacy Protection Agency (CalPrivacy) has launched its first formal sectoral privacy audit, targeting gig-economy platforms to assess whether workers and consumers can meaningfully exercise their rights under the California Consumer Privacy Act (CCPA).

What the Audit Covers

Gig economy platforms, including app-based transportation, delivery, and task-service companies, collect extensive personal information from both consumers and the independent contractors who power their services. That information may include precise geolocation data, behavioral and performance metrics, biometric identification data, financial information, and communications records. Algorithmic systems then process this data to make consequential determinations about workers' dispatch assignments, performance ratings, earnings, and account status, including suspension or deactivation.

CalPrivacy's audit will examine whether workers and consumers can exercise their legal right to know what data is being collected, how it is being used, and with whom it is being shared. The agency will also evaluate whether platforms process access requests within the CCPA's 45-day statutory window, whether responses are complete, and whether platforms have implemented systems that enable individuals to exercise their rights effectively.

CalPrivacy's Chief Privacy Auditor, Sabrina Ross, framed the initiative in practical terms, noting that a gig worker cannot contest an algorithmic determination without access to the underlying data. The agency described the audit as responsive to consumer complaints and comments received during public rulemaking, and as part of a broader effort to increase compliance through proactive review rather than relying solely on individual enforcement actions. The audit authority derives from California Civil Code section 1798.199.40, which directs CalPrivacy to audit businesses for compliance with the CCPA.

Why Workforce Data Matters Here

One of the most significant features of California's privacy framework is its application to workforce data. Of the more than 20 comprehensive state data privacy laws now in effect across the country, the CCPA is unique in extending privacy rights to employees, job applicants, and independent contractors. Most other state privacy laws are limited to consumer data.

This makes the audit particularly consequential for gig economy businesses. A platform may have developed robust procedures for handling consumer access requests while having far less control over the personal information collected from its independent contractors and workers. That data may be scattered across multiple systems, from contractor-management platforms and mobile applications to geolocation databases, background-screening systems, and automated tools that influence earnings, ratings, and account status.

A Shifting Enforcement Landscape

CalPrivacy's move into sectoral audits represents a notable escalation. Historically, the agency and its regulators focused on traditional consumer-facing data practices. t. Although the CCPA originally provided temporary exemptions for much employee and applicant data, those exemptions expired on January 1, 2023. Since then, employees, job applicants, and independent contractors have been able to exercise many of the same CCPA rights available to traditional consumers. Even after those exemptions expired, however, the statute and implementing regulations provided relatively little guidance tailored specifically to the workplace context.

That trend has changed. Regulations approved in late 2025 introduced extensive new requirements affecting employers, including detailed and documented risk-assessment obligations for common data-processing activities and restrictive requirements governing the use of automated decision-making technologies in employment-related contexts.

The enforcement stakes are also meaningful. CalPrivacy’s enforcement activity has increased substantially, with recent CCPA penalties ranging from several hundred thousand dollars to more than $1 million, in addition to numerous enforcement actions involving data brokers. Under the CCPA, the agency may impose administrative fines of up to $7,988 per violation, and those fines can accumulate quickly when an organization fails to respond to multiple data rights requests or has systemic deficiencies in its privacy program. The period in which violations resulted only in a warning appears to have ended.

What Businesses Should Do Now

Gig economy platforms and other businesses subject to the CCPA should consider conducting an internal review before receiving an audit inquiry. That review should focus on whether privacy notices accurately reflect actual data-collection and data-use practices, whether online and telephone request channels function properly and are actively monitored, whether identity-verification procedures are consistent, and whether responses to access requests account for information held across all systems, including those maintained by vendors and service providers.

Businesses should also confirm that personnel responsible for responding to privacy requests understand how to process requests involving workforce data, and that vendor contracts clearly address privacy responsibilities, data access, cooperation with requests, and deletion obligations.

Broader Implications

Although this audit targets gig economy platforms, its significance reaches further. Employers across industries collect and use substantial amounts of workforce data through productivity software, communications tools, location-monitoring systems, AI platforms, background checks, and employee analytics. CalPrivacy's approach to evaluating workforce-privacy programs in this audit may set the standard for how the agency examines employers more broadly.

Employers should avoid treating workplace privacy as separate from their broader privacy-compliance obligations. Workforce data should be included in privacy inventories, vendor reviews, information-security assessments, retention schedules, and response procedures.

Bottom Line

CalPrivacy's first sectoral audit sends a clear signal: California privacy rights must work in practice, not merely appear in a written policy. Businesses should be prepared to demonstrate that they can identify personal information collected from workers and consumers, explain how it is used, respond accurately to access requests, and account for data processed by automated systems and third-party vendors.

The audit also signals that workplace privacy will receive heightened regulatory attention in California. Businesses that collect workforce data should review their privacy programs now and address any gaps before those deficiencies lead to complaints or enforcement actions.

If you have any questions or need assistance, contact us at Eanet, PC.

_____

About the Author

Matthew L. Eanet, Esq.

Matt is managing shareholder at Eanet, PC, a Los Angeles litigation boutique he founded in 2012. He's an expert in complex commercial litigation matters involving real estate, employment, trade secret, trademark and trade dress, data breach, privacy and general business disputes, served as a U.S. Army JAG prosecutor, and has been selected by Super Lawyers (California) every year from 2015-2026.

Full Bio | LinkedIn

Reviewed August 2026

Related Posts
  • Can a Foreign Forum Selection Clause Strip a California Shareholder’s Inspection Rights When the Company’s Principal Place of Business is California? Read More
  • California Aligns State Arbitration Law with Federal Arbitration Exclusions Read More
  • Republicans Seek to Establish National Standards for Protecting Privacy Rights Read More
/